Junglewise Threat Intelligence

CVE-2026-31612: Linux Kernel ksmbd information leak in smb2_get_ea

CVE-2026-31612 · Severity: high · CVSS 7.5 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ksmbd component, which provides SMB file sharing services, could allow an attacker to access sensitive information. By sending a specially crafted request, an attacker can cause the server to leak uninitialized memory from its internal storage (the heap). This could result in the exposure of private data or system information to unauthorized users over the network.

Technical details

A vulnerability exists in the ksmbd module of the Linux kernel within the smb2_get_ea() function. The function reads the EaNameLength value from a client-supplied SMB2 request and uses it as a length parameter for strncmp() without verifying that the length is within the bounds of the actual input buffer. An attacker can exploit this lack of validation to trigger out-of-bounds reads, potentially leaking uninitialized heap memory back to the client. The issue is resolved by adding proper bounds checking against the InputBufferLength and the overall request size. Patches have been released for multiple stable kernel branches including 5.15, 6.6, 6.12, 6.18, 6.19, and 7.0.

Affected products

  • Linux Linux Kernel 5.15 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-06: patched: Initial patch authored by Greg Kroah-Hartman

References

Related threats